Account owners and admins can use System for Cross-Domain Identity Management (SCIM) to provision users and groups from Microsoft Entra ID (formerly Azure Active Directory) to applications automatically. For the Entra ID side, follow Microsoft's guide to provisioning users and groups with SCIM.
Requirements
- Advanced Authentication + User Management
Robin offers a pre-configured SAML app in the Azure Marketplace.
To learn more, see Robin in the Azure Marketplace.
Generate a SCIM token in Robin
Entra ID uses this token to connect to Robin.
- Sign in to your Robin account dashboard: https://dashboard.robinpowered.com/login
- Go to Manage > Integrations.
- Under Add Connectors, search for Microsoft Entra ID and select Set up directory sync. You can also use the SCIM provisioning tile. It shows Manage when SCIM is already set up. The SCIM Provisioning page opens.
- Select Generate Token for SCIM. Robin shows the token only once.
- Copy the token. You paste it into the Secret Token field in Entra ID.
If you lose the token, select Revoke Token, then generate a new one and enter it in Entra ID. Provisioning stops until you do. People already in Robin stay in Robin.
Set up provisioning in Entra ID
Create an app in Entra ID, connect it to Robin with the token, and choose who to provision.
Create the app
- In the Microsoft Entra admin center, go to Enterprise Applications.
- Select New application > Create your own application > Non-gallery application.
- Enter a name for your application.
- Select Add to create an app object.
Connect the app to Robin
- Select Provisioning in the left column.
- In the Provisioning Mode menu, select Automatic. The Admin Credentials section opens.
-
In the Tenant URL field, enter the URL of the application's SCIM endpoint:
https://api.robinpowered.com/v1.0/scim-2 - In the Secret Token field, paste the token you generated in Robin.
- To check the connection, select Test Connection.
- Under Settings, set the Scope to Sync only assigned users and groups.
Assign people and start provisioning
- In the left menu, under Manage, select Users and Groups.
- Add the users and groups you want to provision to Robin.
- In the Provisioning tab, select Start Provisioning.
Users should appear in your Robin account within a few minutes.
User attribute mapping
The preconfigured app does not support the department attribute.
Robin requests these User attributes. Each Robin attribute maps from an Entra ID attribute. Robin uses the work email as the person's email address in Robin, so map it from mail, the person's mailbox address. Do not map it from userPrincipalName: the sign-in name can differ from the mailbox address.
| Robin attribute | Entra ID attribute | Matching precedence |
|---|---|---|
userName |
userPrincipalName |
1 |
emails[type eq "work"].value |
mail |
|
externalId |
objectId |
2 |
active |
Switch([IsSoftDeleted], , "False", "True", "True", "False") |
|
displayName |
displayName |
|
title |
jobTitle |
|
name.givenName |
givenName |
|
name.familyName |
surname |
|
name.formatted |
Join(" ", [givenName], [surname]) |
|
urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:department |
department |
|
urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:manager |
manager |
Turn on the Create, Update and Delete target object actions.
These Optional user attributes are also available:
departmentcostCenterdivisionemployeeNumberlocaletitlemanagerpreferredLanguage
To sync optional attributes, create a new attribute mapping, choose the fields and set the correct schema. For example, to sync department, select Add New Mapping and map the Entra ID attribute department to urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:department. Use these schemas:
- For
title,localeorpreferredLanguage, use the core user schema,urn:ietf:params:scim:schemas:core:2.0:User. - For
department,costCenter,division,employeeNumberormanager, use the enterprise user schema,urn:ietf:params:scim:schemas:extension:enterprise:2.0:User.
Group attribute mapping
Set up the group attribute mapping in Entra ID, with the Create, Update and Delete target object actions turned on. Robin requests these Group attributes. Each Robin attribute maps from an Entra ID attribute:
| Robin attribute | Entra ID attribute | Matching precedence |
|---|---|---|
displayName |
displayName |
1 |
externalId |
objectId |
|
members |
members |
Sync managers
To sync managers into Robin, add the manager attribute to the mappings. Its value should match the manager's externalId in Entra ID.
For example, UserA has the Entra ID 3cd19cd0-ba07-4171-86db-50d8d7694e19, and UserB has the Entra ID 01972a50-2801-4f06-a403-b41f9f04206e. To make UserA the manager of UserB, set the manager field of UserB to 3cd19cd0-ba07-4171-86db-50d8d7694e19. This value is UserA’s Entra ID.
You find the Entra ID in the user’s profile in Entra ID, under Overview > Object ID.
Entra ID must send each user’s Entra ID as externalId. The manager must also be provisioned to Robin through SCIM, in the same Robin organization.
Robin links managers every 3 hours. It links only people whose record changed since the previous evening. If you add the manager later, change any attribute on the employee so your identity provider sends an update. Robin then links the manager.